Escalating SSRF in a Vulnerable Jira Instance to RCE via Docker Engine API
https://ift.tt/2FKCe9m
Submitted November 29, 2018 at 11:13AM by payloadartist
via reddit https://ift.tt/2RmiiLo
https://ift.tt/2FKCe9m
Submitted November 29, 2018 at 11:13AM by payloadartist
via reddit https://ift.tt/2RmiiLo
Development Security Downloads Education | Andmp
Escalating SSRF in a Vulnerable Jira Instance to RCE via Docker Engine API
Download PDF books study material Regular updates on education Tips on money making through Adsense and affiliate programmes and tricks
Huawei Experiences a Major Blow as New Zealand Bans It For Security Reasons
https://ift.tt/2P3mSMF
Submitted November 29, 2018 at 05:03PM by nagishiv0
via reddit https://ift.tt/2zzCum5
https://ift.tt/2P3mSMF
Submitted November 29, 2018 at 05:03PM by nagishiv0
via reddit https://ift.tt/2zzCum5
reddit
r/netsec - Huawei Experiences a Major Blow as New Zealand Bans It For Security Reasons
16 votes and 0 comments so far on Reddit
Leveraging Gradle Plugin wildcard versions for remote code execution
https://ift.tt/2SgAOVx
Submitted November 29, 2018 at 08:11PM by Fido488
via reddit https://ift.tt/2TW3tkj
https://ift.tt/2SgAOVx
Submitted November 29, 2018 at 08:11PM by Fido488
via reddit https://ift.tt/2TW3tkj
Medium
Leveraging Gradle Plugin wildcard versions for remote code execution
Exploit allowed any Gradle Plugin on the Gradle Plugin Portal to have it’s artifact coordinates hijacked by a malicious actor.
Hacking keyboards using QMK
https://ift.tt/2r93rZe
Submitted November 29, 2018 at 07:57PM by mthbernardes
via reddit https://ift.tt/2KH7KE9
https://ift.tt/2r93rZe
Submitted November 29, 2018 at 07:57PM by mthbernardes
via reddit https://ift.tt/2KH7KE9
GitHub
mthbernardes/QMKhuehuebr
Trying to hack into keyboards. Contribute to mthbernardes/QMKhuehuebr development by creating an account on GitHub.
Tyton - Kernel-Mode Rootkit Hunter
https://ift.tt/2FX5gD0
Submitted November 29, 2018 at 07:54PM by ImZugzwang
via reddit https://ift.tt/2BGnhBk
https://ift.tt/2FX5gD0
Submitted November 29, 2018 at 07:54PM by ImZugzwang
via reddit https://ift.tt/2BGnhBk
GitHub
nbulischeck/tyton
Kernel-Mode Rootkit Hunter. Contribute to nbulischeck/tyton development by creating an account on GitHub.
ekoparty 2018 videos (English/Spanish)
https://www.youtube.com/playlist?list=PLaIv9WEAzYZPwyGTRZV85NSGaEe3EbJQ9
Submitted November 29, 2018 at 09:44PM by albinowax
via reddit https://ift.tt/2DQJZrH
https://www.youtube.com/playlist?list=PLaIv9WEAzYZPwyGTRZV85NSGaEe3EbJQ9
Submitted November 29, 2018 at 09:44PM by albinowax
via reddit https://ift.tt/2DQJZrH
YouTube
ekoparty 14 (2018) - YouTube
How to create the perfect anonymizing botnet by abusing UPnP features — and without any infection
https://ift.tt/2SkqBr0
Submitted November 29, 2018 at 10:56PM by anotherinfosecdude
via reddit https://ift.tt/2QmdbxB
https://ift.tt/2SkqBr0
Submitted November 29, 2018 at 10:56PM by anotherinfosecdude
via reddit https://ift.tt/2QmdbxB
Just another infosec blog type of thing
Hiding Through a Maze of IoT Devices
How to create the perfect anonymizing botnet by abusing UPnP features — and without any infection
Fragmented SQL Injection Attacks – The Solution
https://ift.tt/2rbfZPF
Submitted November 29, 2018 at 10:41PM by ziyahanalbeniz
via reddit https://ift.tt/2FLoXxn
https://ift.tt/2rbfZPF
Submitted November 29, 2018 at 10:41PM by ziyahanalbeniz
via reddit https://ift.tt/2FLoXxn
Netsparker
Fragmented SQL Injection Attacks – The Solution
In this blog post, we discuss the research on Fragmented SQL Injection where the hackers control two entry points in the same context in order to bypass the authentication form. Our security researcher looks at the importance of single quotes and the solution…
Hunting with ꓘamerka 2.0 aka FIST (Flickr, Instagram, Shodan, Twitter)
https://ift.tt/2E4VZXM
Submitted November 29, 2018 at 11:29PM by Mysterii8
via reddit https://ift.tt/2TXbpSA
https://ift.tt/2E4VZXM
Submitted November 29, 2018 at 11:29PM by Mysterii8
via reddit https://ift.tt/2TXbpSA
Medium
Hunting with ꓘamerka 2.0 aka FIST (Flickr, Instagram, Shodan, Twitter)
TL;DR ꓘamerka has new cool features, right now you can search for Flickr and Instagram photos, printers and cameras from Shodan and…
Pervasive Brazilian financial malware targets bank customers in Latin America and Europe
https://ift.tt/2Rs9YKg
Submitted November 30, 2018 at 12:06AM by Eliad-Cybereason
via reddit https://ift.tt/2TTK9Em
https://ift.tt/2Rs9YKg
Submitted November 30, 2018 at 12:06AM by Eliad-Cybereason
via reddit https://ift.tt/2TTK9Em
Cybereason
Pervasive Brazilian financial malware targets bank customers in Latin America and Europe
Cybereason’s Nocturnus team mapped out the multi-stage malware distribution infrastructure behind Brazilian financial malware and found that Brazilian-made malware have become pervasive and target over 60 banks in nearly a dozen countries throughout Latin…
GitHub - quarantyne/quarantyne: Modern Web Firewall: stop account takeovers, weak passwords, cloud IPs, DoS attacks, disposable emails
https://ift.tt/2Pkv1jM
Submitted November 30, 2018 at 12:46AM by SoldierGarrison
via reddit https://ift.tt/2FOn5nC
https://ift.tt/2Pkv1jM
Submitted November 30, 2018 at 12:46AM by SoldierGarrison
via reddit https://ift.tt/2FOn5nC
GitHub
quarantyne/quarantyne
Modern Web Firewall: stop account takeovers, weak passwords, cloud IPs, DoS attacks, disposable emails - quarantyne/quarantyne
VulnHub - Vulnix CTF Walkthrough
https://ift.tt/2SkcLVR
Submitted November 30, 2018 at 03:31AM by kindredsec
via reddit https://ift.tt/2zzztSI
https://ift.tt/2SkcLVR
Submitted November 30, 2018 at 03:31AM by kindredsec
via reddit https://ift.tt/2zzztSI
Kindred Security
VulnHub – Vulnix Write-up
Vulnhub Page: Vulnix is a super old machine (from around 2012) that has a pretty sizable amount of exploitation paths, especially for Privilege Escalation. Since the machine is an Ubuntu 12.04 mach…
Source Code Disclosure in Facebook via Ads API
https://ift.tt/2TYZ1kU
Submitted November 30, 2018 at 07:55AM by payloadartist
via reddit https://ift.tt/2AyWN2O
https://ift.tt/2TYZ1kU
Submitted November 30, 2018 at 07:55AM by payloadartist
via reddit https://ift.tt/2AyWN2O
reddit
r/netsec - Source Code Disclosure in Facebook via Ads API
1 vote and 0 comments so far on Reddit
Metadata Endpoints of Various Cloud Services for Fuzzing for SSRF
https://ift.tt/2TYmXVq
Submitted November 30, 2018 at 07:52AM by payloadartist
via reddit https://ift.tt/2AyWNQm
https://ift.tt/2TYmXVq
Submitted November 30, 2018 at 07:52AM by payloadartist
via reddit https://ift.tt/2AyWNQm
Gist
Cloud Metadata Dictionary useful for SSRF Testing
Cloud Metadata Dictionary useful for SSRF Testing - cloud_metadata.txt
Passive-ish Reconnaissance using OSINT: Part I
https://ift.tt/2AydVFZ
Submitted November 30, 2018 at 07:40AM by payloadartist
via reddit https://ift.tt/2TX7MvR
https://ift.tt/2AydVFZ
Submitted November 30, 2018 at 07:40AM by payloadartist
via reddit https://ift.tt/2TX7MvR
Secjuice.com
Passive Reconnaissance Using OSINT
This article explores the basics of OSINT from a reconnaissance perspective, in which we map out the entire public facing infrastructure of a target.
Netflix Information Security: Preventing Credential Compromise in AWS
https://ift.tt/2raRPFf
Submitted November 30, 2018 at 10:57AM by digicat
via reddit https://ift.tt/2RkharD
https://ift.tt/2raRPFf
Submitted November 30, 2018 at 10:57AM by digicat
via reddit https://ift.tt/2RkharD
Medium
Netflix Information Security: Preventing Credential Compromise in AWS
by Will Bengtson
[TOOL] Scrooge McEtherface - Ethereum smart contract auto-looter
https://ift.tt/2rfWKV7
Submitted November 30, 2018 at 02:05PM by berndtzl
via reddit https://ift.tt/2rfWNAh
https://ift.tt/2rfWKV7
Submitted November 30, 2018 at 02:05PM by berndtzl
via reddit https://ift.tt/2rfWNAh
Medium
Automated Smart Contract Exploitation and Looting
In my previous article I showed that Mythril Classic can discover non-trivial vulnerabilities in Ethereum smart contracts and compute the…
UK NCSC discloses their equities process
https://ift.tt/2RnzQGY
Submitted November 30, 2018 at 03:20PM by handmadeby
via reddit https://ift.tt/2AycXcI
https://ift.tt/2RnzQGY
Submitted November 30, 2018 at 03:20PM by handmadeby
via reddit https://ift.tt/2AycXcI
www.ncsc.gov.uk
Equities process
Dr Ian Levy talks about the risks and benefits of disclosing vulnerabilities and explains how the GCHQ Equities Process works.
Modern web application bugs [video]
https://youtu.be/tqFqN8A7waQ
Submitted November 30, 2018 at 04:29PM by albinowax
via reddit https://ift.tt/2zAk6cI
https://youtu.be/tqFqN8A7waQ
Submitted November 30, 2018 at 04:29PM by albinowax
via reddit https://ift.tt/2zAk6cI
YouTube
Modern web application bugs - Erlend Oftedal
With the emerging popularity of bug bounty programs, lesser known and even brand new vulnerability classes are gaining popularity. This talk will give a walk...
fuzz.txt - potentially dangerous files for dirbusting
https://ift.tt/2Jbsi59
Submitted November 30, 2018 at 04:01PM by i_bo0om
via reddit https://ift.tt/2FOry9D
https://ift.tt/2Jbsi59
Submitted November 30, 2018 at 04:01PM by i_bo0om
via reddit https://ift.tt/2FOry9D
GitHub
Bo0oM/fuzz.txt
Potentially dangerous files. Contribute to Bo0oM/fuzz.txt development by creating an account on GitHub.
Marriott hack hits 500 million guests
https://ift.tt/2zvm7qI
Submitted November 30, 2018 at 06:12PM by Koko0404
via reddit https://ift.tt/2Pa8Sk8
https://ift.tt/2zvm7qI
Submitted November 30, 2018 at 06:12PM by Koko0404
via reddit https://ift.tt/2Pa8Sk8
BBC News
Marriott hack hits 500 million guests
The hotel chain says details of up to 500 million guests may have been accessed in a database breach.